Security

Designed around trust, isolation and accountability.

SS Recruit is moving into production MVP with a focus on authentication, organization resolution, RLS, candidate events and secure server-side AI.

AuthRole basedDataOrg scopedAuditEvent tracked

Trust stack

Security is designed into the workflow, not bolted on later.

The product is being hardened around tenant boundaries, role permissions, auditable candidate activity and server-side AI execution.

Role based

Authentication

User identity and role resolution

Org locked

Organization scope

Every record belongs to the right tenant

Policy ready

Database policies

RLS protects candidates, notes and events

Traceable

Operational audit

Candidate events create accountability

Organization isolation

Tenant-aware services and database policies keep customer data scoped by organization.

Role-based access

CEO, Admin, Recruiter, Client and Affiliate permissions are modeled around real workflows.

RLS-ready Postgres

Supabase/Postgres policies are being hardened around profiles, organizations and candidate records.

Audit trails

Candidate events track important actions such as created, updated, CV uploaded and interview scheduled.

Secure AI usage

AI provider keys stay server-side only and Copilot outputs are cached with cost/run metadata.

Production posture

The roadmap now prioritizes trust, persistence, lifecycle events and multi-tenant correctness.

Ready for serious recruiting operations

Turn applicant tracking into a recruiting operating system.

Show clients a product that manages intake, calls, scheduling, source intelligence and candidate visibility from one workspace.

IntakeOutreachSchedulingAnalytics